SafePal warns of data breach affecting nearly 40,000 customers

Cryptocurrency hardware wallet provider SafePal has disclosed a data breach affecting approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026, according to a security advisory published Sunday. The breach exposed names, email addresses, shipping addresses, phone numbers, and purchase information after a flaw in the company's order-tracking function was exploited by a threat actor, who is now claiming to sell the stolen data on a cybercrime forum.
SafePal said the breach did not expose wallet seed phrases, private keys, passwords, bank account information, payment card numbers, or government credentials, and there is "no evidence" the incident compromised access to SafePal wallets or funds. The company discovered an authorization flaw in an order-tracking plug-in during a July security investigation and has since fixed the vulnerability and implemented additional security measures. SafePal is warning customers to watch for targeted phishing emails and phone calls about firmware upgrades, product returns, or refunds, and has already taken down more than 30 fraudulent websites and phishing links tied to the incident, Lawrence Abrams reports for BleepingComputer.